Paloaltonetworks Prisma Access Agent — known CVE vulnerabilities
Every CVE whose affected-product data names Paloaltonetworks Prisma Access Agent, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (12)
CVE-2026-0246 — CVSS 7.8 (high): A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated…
CVE-2026-0294 — CVSS 7.8 (high): A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local…
CVE-2026-0271 — CVSS 7.8 (high): A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to…
CVE-2026-0247 — CVSS 7.8 (high): Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attacker to bypass…
CVE-2026-0278 — CVSS 7.8 (high): Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to…
CVE-2026-0292 — CVSS 6.0 (medium): An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local…
CVE-2026-0293 — CVSS 6.0 (medium): A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the…
CVE-2026-0277 — CVSS 5.9 (medium): An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle…
CVE-2026-0248 — CVSS 5.9 (medium): An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a…
CVE-2026-0245 — CVSS 5.5 (medium): Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and…
CVE-2026-0291 — CVSS 4.4 (medium): An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that…
CVE-2026-0268 — CVSS 4.4 (medium): A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN…